Framework overlap

Does NIST SP 800-190 cover BRCGS Global Standard for Food Safety Issue 9?

You hold NIST SP 800-190 and have been told to do BRCGS Global Standard for Food Safety Issue 9. Here is how much overlaps, control by control.

21% of BRCGS Global Standard for Food Safety Issue 9 you already have

NIST SP 800-190 already covers about 21% of BRCGS Global Standard for Food Safety Issue 9, leaving 31 of 39 controls as genuinely new work.

Already covered 3 Likely covered 5 New work 31

What is genuinely new work

Nothing in NIST SP 800-190 reaches these. This is the list to scope.

2.1
Internal Data Flow Security
2.2
Security Updates
2.3
System Hardening
2.4
Utilize Automated Software Inventory Tools
4.5
Implement and Manage a Firewall on End-User Devices
4.6
Securely Manage Enterprise Assets and Software
5.4
Establishing Audit Programme
BRCGS-1.1
Senior Management Commitment
BRCGS-1.2
Food Safety Culture Plan
BRCGS-2.1
HACCP Team and Prerequisite Programmes
BRCGS-2.2
Hazard Analysis
BRCGS-2.3
Critical Control Points
BRCGS-3.1
Food Safety and Quality Manual
BRCGS-3.11
Product Recall and Withdrawal
BRCGS-3.4
Internal Audits
BRCGS-3.5
Supplier Approval and Performance Monitoring
BRCGS-3.9
Traceability
BRCGS-4.1
Site Standards and Layout
BRCGS-4.10
Foreign Body Detection
BRCGS-4.11
Housekeeping and Hygiene
BRCGS-4.13
Pest Management
BRCGS-4.3
Security and Food Defence
BRCGS-4.9
Chemical and Physical Product Contamination Control
BRCGS-5.1
Product Design and Development
BRCGS-5.3
Allergen Management
BRCGS-5.4
Product Authenticity and Claims
BRCGS-5.5
Product Packaging
BRCGS-6.1
Control of Operations
BRCGS-6.3
Calibration and Control of Measuring Devices
BRCGS-7.1
Training
BRCGS-7.2
Personal Hygiene
Show the 8 you already have
1.2
Operating System Privileged Account Control
1.3
Virtualisation Platform Protection
3.3
Configure Data Access Control Lists
1.1
SWIFT Environment Protection
3.1
Physical Security
3.2
Establish and Maintain a Data Inventory
3.4
Enforce Data Retention
3.5
Securely Dispose of Data

How this is calculated

Already covered means a mapping runs from a control in NIST SP 800-190 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition